Embedded Security Hardware Proxy for Virtualized Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized environments, the security-enhanced capabilities of embedded security hardware on computing devices cannot be utilized, as virtualizing this hardware compromises its inherent security and makes it vulnerable to misuse.
Innovation Solution
A proxy architecture that leverages the embedded security hardware of a client computing device within a virtualized environment hosted by a host computing device, using client and host proxies to intercept and relay security requests and responses, allowing the embedded security hardware to be used as if it were part of the host computing device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If embedded security hardware is virtualized to enable access within virtualized environments, then the hardware becomes accessible and usable, but its inherent security is compromised and it becomes vulnerable to misuse
Solution Approach 1:
A proxy component is introduced as an intermediary between the virtualized environment and the embedded security hardware. The proxy intercepts security requests from virtual machines, relays them to the physical embedded security hardware, and returns responses to the virtual machines. This mediator approach allows virtual machines to access security capabilities without directly virtualizing the hardware, thereby maintaining security integrity while enabling accessibility.
2Ease of operation
If embedded security hardware is directly accessed by virtual machines, then security capabilities are available to applications, but unauthorized access and misuse become possible
Solution Approach 1:
The proxy serves as a controlled intermediary that all security requests must pass through. It validates requests, manages authentication, and controls access to the embedded security hardware. This ensures that applications can access security capabilities through a standardized interface while the proxy prevents unauthorized access and misuse by enforcing security policies.
Solution Approach 2:
The proxy implements feedback mechanisms to monitor and control access to embedded security hardware. It tracks security operations, validates request authenticity, and can revoke or modify access based on security conditions. This feedback loop ensures that security capabilities are available to authorized applications while preventing unauthorized use.
Data Source
AI summary
A host proxy executable within a virtualized environment hostable by a host computing device for a client device intercepts an embedded security hardware communication request sent by an application executable within the virtualized environment. The host proxy sends the embedded security hardware communication request to a client proxy executable on the client computing device. The client proxy relays the embedded security hardware communication request to embedded security hardware of the client computing device.


